Watch the detailed video tutorial below, or continue reading for the step-by-step guide!
Active Directory is the keys to the kingdom. If a threat actor breaches AD, they own your entire company. Use this checklist to harden your AD environment.
Separate your IT admins into tiers. Tier 0 admins (Domain Admins) should only log into Domain Controllers. They should NEVER use their high-privilege credentials to log into a standard user's workstation, which prevents credential harvesting (Pass-the-Hash).
Run regular PowerShell scripts to disable and delete user and computer accounts that haven't logged in for 90 days. Ghost accounts are a massive security liability.
Ensure that IT staff and executives have much stricter password length and rotation requirements than standard employees.
Windows 11 Pro 2 minutes ago